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Abstract 

Domain descriptions in reasoning about actions are 
logical theories and as such they may also evolve. 
Given that, knowledge engineers also need revision 
tools to incorporate new incoming laws about the 
dynamic environment. Here we fill this gap by pro- 
viding an algorithmic approach for revision of ac- 
tion laws. We give a well defined semantics that 
ensures minimal change w.r.t. the original models, 
and show correctness of our algorithms w.r.t. the 
semantic constructions. 



1 Introduction 

Like any logical theory, action theories in reasoning about 
actions may evolve, and thus need revision methods to ade- 
quately accommodate new information about the behavior of 
actions. Recently, update and contraction-based methods for 
action theory change have been defined [Eiter et al, 2005; 
Herzig et al, 2006; Varzinczak, 2008]. Here we continue 
this important though quite new thread of investigation and 
develop a minimal change approach for revising laws of an 
action domain description. 

The motivation is as follows. Consider an agent designed 
to interact with a coffee machine (Figure 1). 



about the behavior of actions in this scenario as a transition 
system (Figure 2). 




Figure 1 : The coffee deliverer agent. 

Among her beliefs, the agent may know that a coffee is a 
hot drink, that after buying she gets a coffee, and that with 
a token it is possible to buy. We can see the agent's beliefs 
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Figure 2: A transition system depicting the agent's knowl- 
edge about the dynamics of the coffee machine, b, t, c, and h 
stand for, respectively, buy, token, coffee, and hot. 

Now, it may be the case that the agent learns that coffee is 
the only hot drink available at the machine, or that even with- 
out a token she can still buy, or that all possible executions of 
buy should lead to states where ^token is the case. These are 
examples of revision with new laws about the dynamics of the 
environment under consideration. And here we are interested 
in exactly these kinds of theory modification. 

The contributions of the present work are as follows: 

• What is the semantics of revising an action theory by a 
law? How to get minimal change, i.e., how to keep as 
much knowledge about other laws as possible? 

• How to syntactically revise an action theory so that its 
result corresponds to the intended semantics? 

Here we answer these questions. 

2 Logical Preliminaries 

Our base formalism is multimodal logic K n [Popkorn, 1994]. 

2.1 Action Theories in Multimodal K 

Let % = {^1,^2, . . . , a n } be the set of atomic actions of a 
domain. To each action a there is associated a modal operator 
a]. ^3 = {Pi,P2i • • • iPn\ denotes the set of propositions, or 
atoms. £ = {p,^p : p G ^3} is the set of literals. £ denotes 
a literal and \£\ the atom in £. 

We use cp, ijj, . . . to denote Boolean formulas. $ is the set 
of all Boolean formulas. A propositional valuation v is a max- 
imally consistent set of literals. We denote by v lh <p the fact 
that v satisfies ip. By val(p) we denote the set of all valua- 
tions satisfying (p. |=p PL is the classical consequence relation. 

Cn(ip) denotes all logical consequences of p. 



With IP((p) we denote the set of prime implicants [Quine, 
1952] of ip. By ir we denote a prime implicant, and atm{ir) 
is the set of atoms occurring in it. Given £ and 7r, £ G ir 
abbreviates '£ is a literal of 7r\ For a given set A, A denotes 

its complement. Hence atm{n) denotes ^3 \ atm(ir). 

We use <£, IF, . . . to denote complex formulas (possibly 
with modal operators). (a) is the dual operator of [a] 

A K n -model is a tuple «/# = (W,R) where W is a set of 
valuations, and R maps action constants a to accessibility re- 
lations R a ^ W x W. Given <y#, 1= p (p is true at world w 

1 w 

of model <y#) if w lh p; h= [al<£ if 1= ^ for every it/ s.t. 

(w,w f ) G 7? fl ; truth conditions for the other connectives are 
as usual. By .A/f we will denote a set of K n -models. 

jtft is a model of <P (noted |= <£) if and only if |= ^ for all 
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w G W. ./# is a model of a set of formulas E (noted = E) 



^ 



if and only if |= ^ for every ^ G E. ^ is a consequence of 
the global axioms E in all K n -models (noted E |= <£) if and 

only if for every j$ , if |= E, then |= <£. 

In K n we can state laws describing the behavior of actions. 
Here we distinguish three types of them. 

Static Laws A static law is a formula p G $ that char- 
acterizes the possible states of the world. An example is 
coffee — > hot. if the agent holds a coffee, then she holds a 
hot drink. The set of static laws of a domain is denoted by S. 

Effect Laws An effect law for a has the form ip — > [a]ip, with 
<£>, ip G 5- Effect laws relate an action to its effects, which can 
be conditional. The consequent ip is the effect that always 
obtains when a is executed in a state where the antecedent 
(p holds. An example is token — > [buy]hot: whenever the 
agent has a token, after buying, she has a hot drink. If ip is 
inconsistent we have a special kind of effect law that we call 
an inexecutability law. For example, ^token — > [Z?wv]JL says 
that buy cannot be executed if the agent has no token. The set 
of effect laws of a domain is denoted by £. 

Executability Laws An executability law for a has the form 
if — > (a)T, with ip G $. It stipulates the context in which a 
is guaranteed to be executable. (In K n (a)T reads "a's exe- 
cution is possible".) For instance, token — > (buy)T says that 
buying can be executed whenever the agent has a token. The 
set of executability laws of a domain is denoted by X. 

Given a, £ a (resp. X a ) will denote the set of only those 
effect (resp. executability) laws about a. 

Action Theories T=<Su£UA , isan action theory. 

2.2 The Frame, Ramification and Qualification 
Problems 

To make the presentation more clear to the reader, we here as- 
sume that the agent's theory contains all frame axioms. How- 
ever, all we shall say here can be defined within a formalism 
with a solution to the frame and ramification problems like 
done by Herzig et al. [2006]. 

Given the acknowledged difficulty of the qualification 
problem, we do not assume here any a priori solution to it. In- 
stead, we suppose the knowledge engineer may want to state 



some (not necessarily fully specified) executability laws for 
some actions. These may be incorrect at the starting point, 
but revising wrong executability laws is an approach towards 
its solution and one of the aims of this work. With further 
information the knowledge engineer will have the chance to 
change them so that eventually they will correspond to the 
intuition (cf. Section 3). 

The action theory of our running example will thus be: 

{coffee — > hot, token —> (buy)T, 
^coffee — > \buy\coffee ^token — > [Z?wv]JL, 
coffee — > [buy]cojfee,hot —> [buy]hot 

Figure 2 above shows a K n -model for the theory T. 

2.3 Supra-models 

Sometimes it will be useful to consider models whose possi- 
ble worlds are all the possible states allowed by S: 

Definition 1 M = (W,R) is a big frame of T if and only if: 

• W — val(S); and 

• R = \J ae ^R a , where 

R a = {(w,w') : \/.(p - 



a 



ib G £, , if 1= p then = , ib\ 



Big frames of Tare not unique and not always models of T. 
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Definition 2 ^ is a supra-model of Tiff |= T and jj£ is a 
big frame ofT. 

Figure 3 depicts a supra-model of our example T. 
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Figure 3: Supra-model for the coffee machine scenario. 

2.4 Prime Valuations 

An atom p is essential to (p if and only if p G atm(ip') for 



all (p f such that hpp,^ ^ ¥ ' • F° r instance, p x is essential to 

~^P\ A (~^Pi V P2J- atm!((p) will denote the essential atoms of 
(p. (If (p is a tautology or a contradiction, then atm!{<p) = 0.) 

For p G 5> (p* is the set of all p' G 5 such that (p |== 
ip' and atm(p') C atmf(p). For instance, p x V /? 2 ^ /?!*, 
as Pi Itpl^i ^^2 but a/m(/7 1 V/7 2 ) ^ citmKjp^). Clearly, 
atm(/\(p*) = atm!(/\cp*). Moreover, whenever |== </p <-> 
<£>', then atm!((p) = atm!(p') and also y?* = <^/*. 



Theorem 1 ([Parikh, 1999]) |= pL 
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(p ^ cp 



atm(p*) C atm((p f ) for every p' s.t. 

Thus for every ip E $ there is a unique least set of elemen- 
tary atoms such that <p may equivalently be expressed using 
only atoms from that set. Hence, Cn(tp) = Cn(p*). 

Given a valuation v, v' C v is a subvaluation. For Wa set of 
valuations, a subvaluation v ; satisfies ip G # modulo W (noted 
v ; 1^ <£>) if and only if v lh y? for all v G W such that v r C v. 

A subvaluation v essentially satisfies p modulo W (v lh' ip) if 

and only if v lb y? and {|^| : £ G v} C atmf(p). 



Definition 3 Let <p G $ and W be a set of valuations. A 
subvaluation v is a prime subvaluation of ip (modulo W) if 

and only ifvlr ip and there is no v C v s.t. v IK (p. 

A prime subvaluation of a formula cp is one of the weakest 
states of truth in which cp is true. (Notice the similarity with 
the syntactical notion of prime implicant [Quine, 1952].) We 
denote all prime sub valuations of (p modulo Why base((p, W). 

Theorem 2 Let ip G # and W be a set of valuations. Then 



v£base((p,W) l\iev 



for all w G W, w lh ip if and only ifw lh V 

2.5 Closeness Between Models 

When revising a model, we perform a change in its structure. 
Because there can be several ways of modifying a model (not 
all of them minimal), we need a notion of distance between 
models to identify those that are closest to the original one. 

As we are going to see in more depth in the sequel, chang- 
ing a model amounts to modifying its possible worlds or 
its accessibility relation. Hence, the distance between two 
K n -models will depend upon the distance between their sets 
of worlds and accessibility relations. These here will be 
based on the symmetric difference between sets, defined as 
X-Y = (X\Y)U(Y\X). 

Definition 4 Let J£ = (W,R). JZ' = (W f ,R / ) is at least as 
close to J£ as Jt" = ( W" , R"), noted Jt 1 <j{ Jt" , ij 

• either W-W' C W-W" 
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• or W-W' = W-W" andR-R! C R-R 

This is an extension of Burger and Heidema's [2002] relation 
to our modal case. Note that other distance notions are also 
possible, like e.g. the cardinality of symmetric differences or 
Hamming distance. (See Section 7 for an explanation on why 
we have chosen this particular distance notion here.) 

3 Semantics of Revision 

Contrary to contraction, where we want the negation of a law 
to be satisfiable, in revision we want a new law to be valid. 
Thus we must eliminate all cases satisfying its negation. 

The idea in our semantics is as follows: we initially have a 
set of models A4 in which a given formula ^ is (potentially) 
not valid, i.e., ^ is (possibly) not true in every model in A4. 
In the result we want to have only models of <£. Adding <P- 
models to A4 is of no help. Moreover, adding models makes 
us lose laws: the resulting theory would be more liberal. 

One solution amounts to deleting from A4 those models 
that are not ^-models. Of course removing only some of 
them does not solve the problem, we must delete every such a 
model. By doing that, all resulting models will be models of 
<£. (This corresponds to theory expansion, when the resulting 
theory is satisfiable.) However, if M. contains no model of 
<£, we will end up with 0. Consequence: the resulting theory 
is inconsistent. (This is the main revision problem.) In this 
case the solution is to substitute each model <J£ in M. by its 
nearest modifications <Jt$ that makes <£ true. This lets us to 
keep as close as possible to the original models we had. 

Before defining revision of sets of models, we present what 
modifications of (individual) models are. 



3.1 Revising a Model by a Static Law 

Suppose that our agent discovers that the only hot drink that is 
served on the machine is coffee. In this case, we might want 
to revise her beliefs with the new static law coffee <-► hot. 

Considering the model in Figure 3, we see that ^coffee A 
hot is satisfiable. As we do not want this, the first step is to 
remove all worlds in which -^coffee A hot is true. The second 
step is to guarantee all the remaining worlds satisfy the new 
law. This issue has been largely addressed in the literature on 
belief revision and update [Gardenfors, 1988; Winslett, 1988; 
Katsuno and Mendelzon, 1992; Herzig and Rifi, 1999]. Here 
we can achieve that with a semantics similar to that of clas- 
sical revision operators: basically one can change the set of 
possible valuations, by removing or adding worlds. 

In our example, removing the possible worlds {f, -ic, h} 
and {-if, -ic, h} would do the job (there is no need to add new 
valuations since the new static law is satisfied in at least one 
world of the original model). 

The delicate point in removing worlds is that it may result 
in the loss of some executability laws: in the example, if there 
were only one arrow leaving some world w and pointing to 
{-if, -ic, h}, then removing the latter from the model would 
make the action under concern no longer executable in w. 
Here we claim that this is intuitive: if the state of the world 
to which we could move is no longer possible, then we do 
not have a transition to that state anymore. Hence, if that 
transition was the only one we had, it is natural to lose it. 

One could also ask what to do with the accessibility rela- 
tion if new worlds must be added (revision case). We claim 
that it is reckless to blindly add new elements to R. Instead, 
we shall postpone correction of executability laws, if needed. 
This approach is debatable, but with the information we have 
at hand, it is the safest way of changing static laws. 

The semantics for revision of one model by a static law is 
as follows: 



Definitions Let Ji = (W,R). Ji' = (W,R f ) e ^f* iff 

W' = (W\val(^(p)) U val(cp) and R' C R. 

Clearly |= (p for all <Jt' G «^£. The minimal models of 
the revision of ^ by cp are those closest to j$ w.r.t. <jt'. 

Definition 6 rev(^Jt ', (p) = |J mm {^^ ^^}- 

In the example of Figure 3, rev(^£ ', coffee ^ hot) is the 
singleton {«/#'}, with ^' as shown in Figure 4. 
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Figure 4: Revising model j% in Figure 3 with coffee ^ hot. 

3.2 Revising a Model by an Effect Law 

Let's suppose now that our agent eventually discovers that 
after buying coffee she does not keep her token. This means 
that her theory should now be revised by the new effect law 



token — > [buy]^token. Looking at model ^ in Figure 3, this 
amounts to guaranteeing that token A {buy) token is satisfiable 
in none of its worlds. To do that, we have to look at all the 
worlds satisfying this formula (if any) and 

• either make token false in each of these worlds, 

• or make (buy) token false in all of them. 

If we chose the first option, we will essentially flip the truth 
value of literal token in the respective worlds, which changes 
the set of valuations of the model. If we chose the latter, 
we will basically remove buy-arrows leading to token-worlds, 
which amounts to changing the accessibility relation. 

In our example, the worlds w\ = {token, coffee, hot}, 
W2 = {token, ^coffee, hot} and ws = {token, ^coffee, ^hot} 
satisfy token A (buy) token. Flipping token in all of them to 
-^token would do the job, but would also have as consequence 
the introduction of a new static law: -^token would now be 
valid, i.e., the agent never has a token! Do we want this? 

We claim that changing action laws should not have as side 
effect a change in the static laws. These have a special status, 
and should change only if required (see Section 3.1). Hence 
each world satisfying token A (buy) token has to be changed 
so that (buy) token becomes untrue in it. In the example, we 
thus should remove (wi,wi), (u>2, w\) and {w%, w\) from R. 

The semantics of one model revision for the case of a new 
effect law is: 



Definition? Let Jt = (W,R). Ji' = (W',R') G JZ, 
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W r = W,R'C R } 



Jt' 



V 



a 



ip, and 



Jt 



• If(w, w') G R\ R', then |= <p 

The minimal models resulting from the revision of a model 
<J( by a new effect law are those closest to M w.r.t. ~<j{\ 



Definition8 rev(^K,(p — > [a]ip) = (Jminj^ 



V-»[a]^ 



^iJt}- 




Taking jM as in Figure 3, rev {^M , token — > \buy\-^tokeri) 
will be the singleton {^'} depicted in Figure 5. 



JC 1 



(-■f,-.c,T) 
Figure 5: Revising jtft in Figure 3 with token — > [buy]^token. 

Note that adding effect laws will never require new arrows. 
This is the job of executability-revision. 

3.3 Revising a Model by an Executability Law 

Let us now suppose that at some stage it has been decided to 
grant free coffee to everybody. Faced with this information, 
we have to revise the agent's laws to reflect the fact that buy 
can also be executed in ^token-contexts: -^token — > (buy)T 
is a new executability law (and hence we will have (buy) T in 
all new models of the agent's beliefs). 

Considering model jtft in Figure 3, we observe that 
^tokenA[buy]-L is satisfiable. Hence we must throw ^tokenA 
[buy] JL away to ensure the new law becomes true. 



To remove ^token A [&mv]J_ we have to look at all worlds 
satisfying it and modify jtft so that they no longer satisfy that 
formula. Given worlds W4 = {^token, ^coffee, ^hot} and 
w$ = {^token, ^coffee, hot}, we have two options: change 
the interpretation of token in both or add new arrows leaving 
these worlds. A question that arises is 'what choice is more 
drastic: change a world or an arrow'? Again, here we claim 
that changing the world's content (the valuation) is more dras- 
tic, as the existence of such a world is foreseen by some static 
law and is hence assumed to be as it is, unless we have enough 
information supporting the contrary, in which case we explic- 
itly change the static laws (see Section 3.1). Thus we shall 
add a new buy- arrow from each of W4 and w$. 

Having agreed on that, the issue now is: which worlds 
should the new arrows point to? In order to comply with min- 
imal change, the new arrows shall point to worlds that are 
relevant targets of each of the ^token-worlds in question. 

Definition 9 Let Jt = (W,R), w, w' G W, and M be a set 



of models s.t. ^C G A4. Then w' is a relevant target world of 
w w.r.t. cp — > (a)T for ^ in M,iff\= (f and 

• If there is Jt' = (W,R') G M such that R' a (w) ^ 0: 

- for all £ G w f \ w, there is ty' G 5 s.t. there is 

v' G base{^)' , W) s.t. v' C w' , £ G v', and |= [a]ip / 
for every jjKi G M, 

- for all £ G wH w' , either there is ip' G # s.t. there is 

Jti r 

a 



v' G base{^)' , W) s.t. v' C w' , £ G v' , and |= [a]ip f 
for all .Mi G Ai; or there is <Mi G M. s.t. \£ \a]->£ 

v w L J 

• IfR' a (w) = for every Jt' = (W \R') G M: 

- for all £ G w'\w, there is j$i = (Wi,Ri) G M. s.t. 
there is u,v G Wi s.t. (u, v) G Ri a and £ G v \ u 

- for all £ G wC\w', there is ^i = (Wi,Ri) G A4 s.t. 
there is u,v G Wi s.t. (u, v) G Ri a and£ G uHv, or 
for all ^i = (Wi,Ri) G A4, if (u,v) G Ri a , then 
-i£ £ v \ u 

By rt(w, (p — > (a)T, ^ , M) we denote the set of all relevant 
target worlds ofw w.r.t. (p — > (a)T for ^ in A4. 

In our example, wq = {^token, coffee, hot} is the only rel- 
evant target world here: the two other -^token- worlds violate 
the direct effect coffee of action buy, while the three token- 
worlds would make us violate the frame axiom -^token — > 
[buy]^token. 

The semantics for one model revision by a new executabil- 
ity law is as follows: 

Definition 10 Let J£ = (W,R). Jt' = (W^R') G Jt. 



ip- 



(a)T 



Jt' 
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• W' = W, R C R', |= (p -► (a)T, and 

• If(w, w f ) G R f \R, then w' G rt(w, (p - 

The minimal models resulting from revising a model ^ 
by a new executability law are those closest to ^ w.r.t. <.j{'> 

Definition 11 rev{^ , (p — > (a)T) = |Jmin{^* / v T , ~<ji}. 

In our running example, rev(<Jt ' , ^token — >- (buy)T) is the 
singleton {^'}, where ^' is as shown in Figure 6. 
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Figure 6: The result of revising model ^# in Figure 3 by the 
new executability law -^token — > (buy)T. 

3.4 Revising Sets of Models 

Up until now we have seen what the revision of single models 
means. Now we are ready for a unified definition of revision 
of a set of models M. by a new law ^ (cf. Section 5): 

Definition 12 Let A4 be a set of models and <& a law. Then 



M* 



$ 



(M\{^:\^$})U (J rev(Jt,<L>) 



.JZeM 



Definition 12 comprises both expansion and revision: in the 
former, addition of the new law gives a satisfiable theory; in 
the latter a deeper change is needed to get rid of inconsistency. 

4 Algorithms for Revision of Laws 

We now turn our attention to the syntactical counterpart of 
revision. Our endeavor here is to perform minimal change 
also at the syntactical level. By 7j we denote the result of 
revising an action theory Twith a new law <&. 

4.1 Revising a Theory by a Static Law 

Looking at the semantics of revision by Boolean formulas, 
we see that revising an action theory by a new static law may 
conflict with the executability laws: some of them may be lost 
and thus have to be changed as well. 

The approach here is to preserve as many executability 
laws as we can in the old possible states. To do that, we 
look at each possible valuation that is common to the new 
S and the old one. Every time an executability used to 
hold in that state and no inexecutability holds there now, 
we make the action executable in such a context. For those 
contexts not allowed by the old S, we make a inexecutable 
(cf. Section 3.1). Algorithm 1 deals with that (here S • p 
denotes the classical revision of S by ip built upon some 
well established method from the literature [Winslett, 1988; 
Katsuno and Mendelzon, 1992; Herzig and Rifi, 1999]. The 
choice of a particular operator for classical revision/update 
is not the main matter here, but rather whether it gives us a 
modified set of static laws entailing the new one). 

In our example, revising the action theory Twith a new 
static law coffee <-> hot will give us 



coffee 



>hot 



= < 



coffee <-> hot, 

(token A coffee A hot) — > (buy)T, 

(token A ^coffee A —hoi) — > (buy)T, 

^coffee — > [buy]coffee, ^token — > [Z?wv]J_, 

coffee — > [buy]coffee,hot — > [buy]hot 



> 



Algorithm 1 Revision by a Static Law 



input: % p 
output: 7^ 

S' '•= S • p /* classically revise S */ 

£' '•= £ /* effect laws remain unchanged */ 

X' : = /* executability laws will be 'recovered' from old T*/ 

for all 7T G IP(S') do 

for all A C atm(ii) do 

Sr A • "■ /\p i ^atm(n) "i l\ i ^atm(Tv) ~~ i P % 

PiEA Pi <£A 

/* by extending tv with (/9a we get a valuation */ 
if <S' ^ PL (7T A pa) — >• J- /* context not removed */ then 
if 5 ^ PL (7T A pa) — ► J- then 

ifT^jTrA^) -► (a)T and £',£', Af ^^(ttA^a) 
then 

'C 1 = {(<£* A7tA(^a) -► (fl)T : pi -> (a)T G A^} 
/* preserve executability law in state not removed */ 
else 

£ , :=£ , U{(7TAp A ) -> [fl]-L} 
7;: = ^U^UA" 



4.2 Revising a Theory by an Effect Law 

When revising a theory by a new effect law p — > [a]^, we 
want to eliminate all possible executions of a leading to ^ - 
states. To achieve that, we look at all (^-contexts and every 
time a transition to some -i^-context is not always the case, 
i.e., T^= p — ► (a)^ip, we can safely force [a]^ for that con- 

text. On the other hand, if in such a context there is always 
an execution of a to -i^, then we should strengthen the exe- 
cutability laws to make room for the new effect in that context 
we want to add. Algorithm 2 below does the job. 



Algorithm 2 Revision by an Effect Law 



a 



4' 



input: % p 
output: T^_ 

for all tt e IP(S A p) do 



[a]ip 



for all A C atm(ii) do 

W := /\ Pi e^)Pi A /\ 



Vi 



Eafm(7r) 
PiEA Pi <£A 

/* by extending 7r with pa we get a valuation */ 
if S ^ PL (7T A pa) — >■ -L /* is an allowed context */ then 
for all tt' G /P(5 A -.^0 do 

if T' |= (7r A (/?a) — ► (fl)^' /* -1-0 is achievable */ 

then 

, (T \ A'l) U {(^ A -.(tt A <p A )) -> ( fl >T : 

/* weaken executability laws */ 

T : = T U {(tt A p A ) -► [a]ip} I* safely add the law */ 
if T ^ (tt A pa) -> [fl] JL then 

T':=V / U{(y? i A7rAy?A) -> (a)T : ^ -> (a)T G 7} 
/* preserve other previous transitions */ 






In our running example, revision of the action theory T 
with the new effect law token — > [buy]-itoken would give us 



7* 

tokens [buy] —>token 



Algorithm 3 Revision by an Executability Law 



< 



> 



coffee — > hot, 
{token A ^(token A coffee A /zctf)) — > (buy)T, 

(token A coffee A /zctf) — > (buy)T, 
(token A ^(token A ^coffee A /z6tf)) — > (buy)T, 

(token A ^coffee A /z6tf) — > (buy)T, 

(token A ^(token A ^coffee A -ihot)) — > (buy)T. 

(token A ^coffee A — i/zo/) — > (buy)T, 

^coffee — > [buy]coffee, ^token —> [buy]-L, 

coffee —> \buy\coffee ,hot — > [buy]hot, 

token — > [buy]-itoken 



Regarding the bunch of new executability laws introduced in 
the resulting theory, observe that they can be easily simplified 
to the single one fo&en — > (buy)T. 



4.3 Revising a Theory by an Executability Law 

Revision of a theory by a new executability law has as conse- 
quence a change in the effect laws: all those laws preventing 
the execution of a shall be weakened. Moreover, to comply 
with minimal change, we must ensure that in all models of 
the resulting theory there will be at most one transition by a 
from those worlds in which Tprecluded a's execution. 



-+< fl >T 

(a)T 



input: % cp 
output: T 

for all 7T E /P(«S A <p) do 
for all A C atm(7r) do 

T 7 ^ /\ Pi eatm(n)ri A /\p i eatm(7r) ~~ "^ i 

PiEA Pi <£A 

/* by extending 7r with ipA we get a valuation */ 

if <S ^ PL (7T A (/?a) — >■ -L /* is an allowed context */ then 



if T' \=^ (tt A ^a) — > [fl]-L then 



(3 



*0i 



(T'\£' B ) U{(^A-(ttA^a))- 

y?i — ► [a]-0i e £' a }u 



T' '-= {(ifi A tt A ip A ) 



A 1 Gatm^Tr') 



<fi 



a 



*l>i e S' a } 



/* weaken the effect laws */ 
for all L C £ do 

if S \^ pl (tt A (p A ) — ► A^gl ^ tnen 
for alU G L do 

ifT^^ [a]±or(T^- 

r fe n ^-> [40 then 

T: = T U {(tt A^aA^ [a]^} 
/* preserve non-affected literals */ 
T' : = T' U {(tt A ip A ) -> (fl)T} /* safely add the law */ 



a 



£ and 



T* . _ /T-7 



Let (£f >- L )i, . . . , (^' ± ) n denote minimum subsets (w.r.t. cutability law -ntoken -> (fcy)T gives us ^ tofe n^<^>T = 



set inclusion) of £ a such that 5, (£^ :± )i \=f? <p [a]JL. 

(According to Herzig and Varzinczak [2007], one can en- 
sure at least one such a set always exists.) Let £~ = 
Ui<i< n (^a ,± )i' The effect laws in £~ will serve as guide- 
lines to get rid of [a] JL in each ip- world allowed by T: they 
are the laws to be weakened to allow for (a)T in (^-contexts. 



< 



Our algorithm works as follows. To force ip — > (a)T to 
be true in all models of the resulting theory, we visit every 
possible (^-context allowed by it and make the following op- 
erations to ensure (a)T is the case for that context: Given a ip- 
context, if Tdoes not always preclude a from being executed 
in it, we can safely force (a)T without modifying other laws. 
On the other hand, if a is always inexecutable in that context, 
then we should weaken the laws in £~ . The first thing we 
must do is to preserve all old effects in all other (^-worlds. 
To achieve that we specialize the above laws to each possible 
valuation (maximal conjunction of literals) satisfying ip but 
the actual one. Then, in the current ^-valuation, we must en- 
sure that action a may have any effect, i.e., from this (^-world 
we can reach any other possible world. We achieve that by 
weakening the consequent of the laws in £~ to the exclusive 
disjunction of all possible contexts in T. Finally, to get mini- 
mal change, we must ensure that all literals in this (^-valuation 
that are not forced to change are preserved. We do this by stat- 
ing a conditional frame axiom of the form (ipk A £) — > [a]£, 
where ipk is the above-mentioned (^-valuation. 

Algorithm 3 gives the pseudo-code for that. 

In our example, revising the action theory Twith the exe- 



> 



coffee —> hot, token —> (buy)T, 

^coffee -> [buy]coffee, 

(-^token A ^(^token A coffee A hot) A 

^(-^token A ^coffee A hot) A 

^(-^token A ^coffee A -ihot)) — > [&wv]_L, 

coffee —> [buy]coffee,hot — > [buy]hot, 

(-^token A coffee A hot) — > \buy\-itoken, 

(-^token A ^coffee A hot) — > \buy\-itoken, 

(-^token A ^coffee A -ihoi) — > \buy\-itoken, 

-^token — > (buy)T 

Again, the resulting theory can be post-processed to give us a 
much more compact representation of the new laws that have 
been added. 

4.4 Complexity Issues 

Algorithms 1-3 terminate. However, they come with a con- 
siderable computational cost: the K n - entailment test with 
global axioms is known to be EXPTlME-complete. Comput- 
ing all possible contexts allowed by the theory is clearly ex- 
ponential. Moreover, the computation of IP(.) might result in 
exponential growth [Marquis, 2000]. 

Given that theory change can be done offline, from the 
knowledge engineer's perspective what is more important is 
the size of the computed contracted theories. In that matter, 
our results are positive: 

Theorem 3 Let Tbe an action theory, and $ be a law. Then 
the size (number of formulas) of 1% is linear in that ofT. 



5 Correctness of the Algorithms 

Suppose we have two atoms p x and/? 2 > an d one action a. Let 
7i = {^p 2 ,Pi — ► [a]p 2 i ( a )^}- The only model of T\ is «/# 
in Figure 7. Revising such a model by /^ V p 2 gives us the 
models <J£[, 1 < z < 3, in Figure 7. Now, revising T\ by 
/?! V/? 2 will give us Ti* iV/ , 2 = {p x A -^ 2 ,/>i -> [^2}- The 
only model of Tj.* v is «^/ in Figure 7. This means that the 

semantic revision may produce models (viz. <J£ 2 and ^3 in 
Figure 7) that are not models of the revised theories. 



Jl 






Jt[ : (KTjpT) 



Figure 7: Model ^ of 7i and revision of jj£ by p : V/? 2 . 

The other way round the algorithms may give theories 
whose models do not result from revision of models of the 
initial theory: let T 2 = {(p 1 V p 2 ) — > [fl]-L, (<z)T}. Its only 
model is <y# (Figure 7). Revising ^ by p : V/? 2 is as above. 
But T2* lVp2 = {Px V/7 2 , {p 1 V p 2 ) -► [a]J_} has a model 

^" = ({{Pl,P2}, {Pl> ^L hPl,P2}}, 0) n0t in ^p\vp 2 ' 

All this happens because the possible states are not com- 
pletely characterized by the static laws. Fortunately, concen- 
trating on supra-models of % we get the right result. 

Theorem 4 If A4 = {^ : ^ is a supra-model of T\ and 

there is JSC e M s.t. |= <P, then \J^ eM rev^Jt ', 0) C M. 

Then, revision of models of Tby a law ^ in the semantics 
produces models of the output of the algorithms 7j: 

Theorem 5 If M = {^ : ^ is a supra-model of T\ ^ 0, 



Jt' 



I <p- 



then for every J%' G M.%, 

Also, models of 7j result from revision of models of Tby ^: 

Theorem 6 If M = {^# : ^ is a supra-model of T\ ^ 0, 



^r' 






then for every <JK' , if |= 7J, //z^/i ^# r G .M 

Sticking to supra-models of Tis not a big deal. We can use 
existent algorithms in the literature [Herzig and Varzinczak, 
2007] to ensure that Tis characterized by its supra-models 
and that M ^ 0. 

6 Related Work 

The problem of action theory change has only recently 
received attention in the literature, both in action lan- 
guages [Baral and Lobo, 1997; Eiter et al, 2005] and in 
modal logic [Herzig et al, 2006; Varzinczak, 2008]. 

Baral and Lobo [1997] introduce extensions of action lan- 
guages that allow for some causal laws to be stated as defea- 
sible. Their work is similar to ours in that they also allow for 
weakening of laws: in their setting, effect propositions can be 
replaced by what they call defeasible (weakened versions of) 
effect propositions. Our approach is different from theirs in 
the way executability laws are dealt with. Here executability 
laws are explicit and we are also able to change them. This 



feature is important when the qualification problem is consid- 
ered (cf. the Introduction). 

The work by Eiter et al. [2005; 2006] is similar to ours in 
that they also propose a framework that is oriented to updat- 
ing action laws. They mainly investigate the case where e.g. 
a new effect law is added to the description (and then has to 
be true in all models of the modified theory). 

In Eiter et al.'s framework, action theories are described 
in a variant of a narrative-based action description language. 
Like in the present work, the semantics is also in terms of 
transition systems: directed graphs having arrows (action oc- 
currences) linking nodes (configurations of the world). Con- 
trary to us, however, the minimality condition on the outcome 
of the update is in terms of inclusion of sets of laws, which 
means the approach is more syntax oriented. 

In their setting, during an update an action theory Tis seen 
as composed of two pieces, T u and T m9 where T u stands for 
the part of Tthat is not supposed to change and T m contains 
the laws that may be modified. In our terms, when revising 
by a static law we would have T m = S U X a , when revising 
by an effect law T m = £ a U X a , and when revising with exe- 
cutability laws Tm = £ ~ U X a . The difference here is that in 
our approach it is always clear what laws should not change 
in a given type of revision, and T u and T m do not need to be 
explicitly specified prior to the update. 

Their approach and ours can both be described as 
constraint-based update, in that the theory change is carried 
out relative to some restrictions (a set of laws that we want to 
hold in the result). In our framework, for example, all changes 
in the action laws are relative to the set of static laws S (and 
that is why we concentrate on supra-models: models of T 
having val(S) as worlds). When changing a law, we want to 
keep the same set of states. The difference w.r.t. Eiter et al.'s 
approach is that there it is also possible to update a theory 
relatively to e.g. executability laws: when expanding Twith a 
new effect law, one may want to constrain the change so that 
the action under concern is guaranteed to be executable in the 
result. 1 As shown in the referred work, this may require the 
withdrawal of some static law. Hence, in Eiter et al.'s frame- 
work, static laws do not have the same status as in ours. 

7 Discussion and Perspectives 

Here we have studied what revising action theories by a law 
means, both in the semantics and at the syntactical (algorith- 
mic) level. We have defined a semantics based on distances 
between models that also captures minimal change w.r.t. the 
preservation of effects of actions. With our algorithms and 
the correctness results we have established the link between 
the semantics and the syntax for theories with supra-models. 
(Due to page limits, proofs have been omitted here.) 

For the sake of presentation, here we have abstracted from 
the frame and ramification problems. However our definitions 
could have been stated in a formalism with a suitable solution 
to them, like e.g. Castilho et al.'s approach [1999]. With re- 
gards to the qualification problem, this is not ignored here: 



! We can emulate that in our approach with two modifications 
of T: first adding the effect law and then an executability law. 



revising wrong executability laws is an approach towards its 
solution. Indeed, given the difficulty of stating all sufficient 
conditions for executability of an action, the knowledge en- 
gineer writes down some of them and lets the theory 'evolve' 
via subsequent revisions. 

The reason why we have chosen such a simple notion of 
distance between models is that with other distances one may 
not always get the intended result. This is better illustrated 
with the contraction counterpart of our operators [Varz- 
inczak, 2008]. Suppose one wants to remove an executability 
law ip — > (a)T. Then we do that by removing a-arrows from 
ip -worlds. Suppose we have a model with two (^-worlds, w\ 
with one leaving a- arrow and w^ with two a-arrows. Then 
with e.g. Dalal's distance [1988], the associated contraction 
operator would always exclude the resulting model in which 
W2 loses its two arrows, simply because deleting 1 arrow 
is Dalai-better than deleting 2. This problem doesn't hap- 
pen with our distance, which gives us a version of maxi- 
choice [Hansson, 1999]. 

One criticism to the approach here developed concerns the 
precedence of static laws in the revision process, which could 
make the revision operators to be interpreted as incoherent. 
As agreed in the literature, however, given that static laws are 
much easier to state, they are more likely to be correct, and 
then it makes sense to give them precedence. Supporting this 
is the fact that most of the attention in the reasoning about 
actions area has been paid to effect laws and executability 
laws, which are much more difficult to completely specify. 
Our approach is in line with that. 

Our next step is to analyze the behavior of our opera- 
tors w.r.t. AGM-like postulates [Alchourron et al, 1985] 
for modal theories and the relationship between our revision 
method and contraction. What is known is that Levi iden- 
tity [Levi, 1977], % = T^ U {<£}, in general does not hold 
for action laws. The reason is that up to now there is no con- 
traction operator for ^ where ^ is an action law. Indeed this 
is the general contraction problem for action theories: con- 
traction of a theory Tby a general formula (like ^ above) is 
still an open problem in the area. The definition of a general 
method will mostly benefit from the semantic modifications 
we studied here (addition/removal of arrows and worlds). 

Given the relationship between modal logics and descrip- 
tion logics, a revision method for DL TBoxes [Baader et al, 
2003] would also benefit from the constructions that we have 
defined here. 
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